Your documents are sensitive. DocFila uses managed-cloud encryption, least-privilege controls, malware scanning, tamper-evident signing evidence, and public vulnerability reporting.
Every document, signature, embedding, and audit log is encrypted at rest with AES-256 by Google Cloud's default encryption. The text DocFila extracts from your documents is encrypted again, field by field, with per-account keys before it is stored. DocFila's servers can derive those keys, so this is not end-to-end encryption.
Production traffic uses HTTPS with HSTS. Exact protocol negotiation depends on the managed hosting edge and supported client.
Google-managed keys protect stored cloud data. Customer-managed keys are on the roadmap and not available today.
Vault items marked Encrypted, or stored with zero-knowledge mode on, are encrypted on your device with AES-256-GCM before upload, with a key DocFila's servers never receive. Items left at Standard are protected by the vault lock and Google's at-rest encryption only.
Stated field by field, so nobody has to infer it. DocFila is not end-to-end encrypted: our servers can read your document text, because search and automation run there. Only the Vault offers a key we never receive.
| Data | Protection | Who can read it |
|---|---|---|
| Everything, in transit | TLS (HTTPS) | The two ends of the connection |
| Everything, at rest | AES-256 by Google Cloud, Google-managed keys (no customer-managed keys) | Google's infrastructure and DocFila's servers |
| Text extracted from your documents, AI summaries, entities found in them, search chunks | Also AES-256-GCM, field by field, with a key for your account derived on our server | You, and DocFila's servers (not end-to-end) |
| Search index words | Replaced by keyed HMAC-SHA256 tokens; no word is stored | No one can read a word back |
| Vault items marked Encrypted, or in zero-knowledge mode | AES-256-GCM on your device before upload | Only a device that holds the key, or someone with the item's password or recovery phrase |
| The uploaded file itself (PDF, image, Word) | At-rest encryption by Google only | You, and DocFila's servers |
| Titles, file names, tags, folders, dates, sizes, most extracted fields, DocFila Studio chat history, Vault Standard items and all vault item names | At-rest encryption by Google only | You, and DocFila's servers |
| Content you send to an AI feature | TLS to Google's Gemini API or Vertex AI | Google, under its terms for those services — see AI data handling |
The engineering version of this table — with the code and the automated tests behind every row — is kept in DocFila's repository as docs/security/ENCRYPTION.md and is shared in full during a security review.
DocFila does not currently claim SOC 2, ISO 27001, or HIPAA certification. Implemented controls and mappings are not independent attestations.
Retention, deletion, legal-hold, access, and audit controls support customer privacy obligations. Contractual terms apply only when executed.
Regulated data requires an architecture and legal review before use. Do not upload PHI unless the required agreement has been executed.
Control mappings support internal readiness and buyer review. Certification will be stated only after an independent auditor issues a current report.
DocFila does not train, fine-tune, or evaluate any model on your documents, and builds no dataset from them. DocFila's AI server functions do not store your request or the answer, and provider error bodies are never logged. Results a feature is meant to keep — a saved summary, your DocFila Studio chat history — stay in your account until you delete them. The named provider and its terms: AI data handling.
Each device has an AI switch: On (the default), Local only, or Off. While it is On, document content goes to Google (Gemini API) when you use an AI feature, and each saved document's text (up to roughly the first 9,000 characters) goes to Google Vertex AI to build your search index. In Local only or Off, no document content is sent to any AI service.
DocFila employees do not read your documents to improve products. Automated quality monitoring uses metadata only.
No model providers, infrastructure, or sub-processors in jurisdictions with mandatory data access laws (PRC, Russia, Iran, North Korea).
Automated rules, secret, artifact, API-contract, malware, and regression gates run before deployment. Independent testing is reported only when completed.
Production telemetry and provider alerts support incident detection. Coverage and response commitments are documented in the customer's support terms.
Database delete protection is on, and Google replicates stored data across zones. Point-in-time recovery, managed backups, and a tested restore are not in place yet, so no RPO or RTO is offered.
One person, the founder, holds production access, and every deploy, rules change, and secret rotation goes through them. What each app user can read and write is enforced by database and storage security rules, tested before release.
Found a security issue? We want to know. Email security@docfila.com with details. The contact is also published at /.well-known/security.txt. We confirm receipt and triage every report by severity.
Security reports are triaged by severity. Reward or safe-harbor terms apply only when confirmed in writing for the submitted report.